Artificial intelligence (AI) is becoming more than a tool for people who want to do something malicious. It is increasingly becoming part of the operational machinery itself.
That is the main message emerging from Anthropic ‘s latest Threat Intelligence report, which examines malicious activity identified and disrupted between December 2025 and August 2026. The cases cover cyber operations, influence campaigns, surveillance, fraud, biological research, conventional weapons and attempts to extract the capabilities of frontier AI models.
The actors involved are equally diverse. Anthropic describes suspected state-sponsored groups, financially motivated criminals, commercial surveillance operators and politically motivated individuals. What connects many of these cases is not a new attack technique, but the way AI changes the economics, speed and scale of operations.
AI is becoming an operational layer
The report makes an important distinction from the usual discussion about AI-powered hacking.
The biggest change may not be that AI can discover a new vulnerability or write malware. It is that models can now contribute across almost the entire attack chain, from reconnaissance and tool development to exploitation, credential theft, data processing and exfiltration.
Anthropic observed operations in which AI systems executed commands against victim networks, harvested credentials and exfiltrated information. At the more autonomous end of the spectrum, multi-agent frameworks conducted reconnaissance, exploitation and data theft against several victims in parallel, sometimes for hours or days with limited human intervention.
This has an important consequence for defenders. Sophisticated attacks no longer necessarily require sophisticated attackers.
According to Anthropic, AI is reducing the gap that once separated well-funded state operations from smaller criminal groups. Reconnaissance, exploitation, coding and data analysis that previously required several specialists can increasingly be delegated to AI systems running at machine speed.
The underlying attacks are often familiar. Stolen credentials, exposed services, vulnerable edge devices, phishing and SQL injection still play a central role. What has changed is the cost of putting them together at scale.
Cybercrime becomes a production line
One of the clearest examples involves a financially motivated operation that harvested credentials from software and online services.
The attackers downloaded and analyzed 1.8 million Android application packages, searching for hardcoded secrets, while running a parallel process to collect GitHub-related credentials. The important point is not the number of apps. It is the automated pipeline connecting discovery, credential collection, validation and subsequent intrusion activity.
“One French-speaking operator going by the aliases of (MeowSHA | frkoo | blazespider) ran a distributed credential-harvesting pipeline across a fleet of 10 AWS EC2 workers. This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with Detecting and countering misuse of AI: September 2026 12 TruffleHog.” reads the report. “Verified findings were routed in real time to a Telegram group organized into over 100 source types. A parallel GitHub organization email harvester fed a second stream of stolen GitHub Personal Access Tokens. These two credential pipelines supplied the initial-access credentials for the bulk of the confirmed breaches associated with frkoo.”
The same model appears elsewhere in the report. Attackers used AI to develop malware and phishing tools, analyze compromised environments, process stolen information and maintain access to victims.
In one campaign, stolen tokens could be replayed against Microsoft services to access mailbox contents, including deleted messages. The attackers used techniques designed to make their traffic resemble legitimate Microsoft clients. Anthropic says Claude was used to engineer and test the tooling.
This is what makes the development significant. AI does not need to invent a completely new attack for the threat level to increase. If it can automate enough of the existing process, a small team can attempt operations that previously required a much larger workforce.
Surveillance at machine speed
The report becomes even more striking when it moves beyond cybercrime.
Anthropic identified nation-state actors and commercial surveillance operators using Claude to build systems for monitoring populations, profiling individuals and analyzing social media activity. The cases involve actors linked to China, Iran and West Africa, as well as the commercial surveillance-for-hire market.
“These cases include threat actors from China, Iran, and West Africa, as well as the commercial “surveillance-for-hire” market, and range from operations carried out by a single individual to entire teams.” continues the report. “Anthropic’s Usage Policy prohibits using Claude to conduct non-consensual surveillance and profiling, and to use our services to violate individuals’ civil liberties and human rights. In every case we describe below, the threat actors violated our Usage Policy and attempted to circumvent controls designed to detect such misuse.”
In one case, a consultant working for Malian national security authorities used Claude to engineer a mass-interception platform capable of monitoring communications across the country’s mobile operators and producing dossiers on targets.
In another, Iranian actors used Claude to develop a malicious Firefox extension designed to harvest information about social-media users. Chinese operators used AI to analyze large volumes of social-media content, identify potential targets and generate intelligence reports.
One particularly revealing operation targeted Uyghur communities in Syria. An actor without Arabic-language skills used Claude to draft messages in the appropriate dialect, translate replies in real time, role-play as an expert to evaluate the operation and prepare the resulting information for a suspected human case officer.
This shows another important shift. AI is not merely analyzing surveillance data after it has been collected. It can become part of the system that decides whom to watch, how to approach them and how to turn raw information into intelligence.
Propaganda can also be industrialized
The same automation is appearing in influence operations.
Anthropic describes an operation linked with high confidence to UAE government officials in which AI supported a network of roughly 300 inauthentic social-media accounts. The operation also created a front NGO using the identity of a real organization, produced apparently independent human-rights material and ghost-wrote testimony intended for presentation to the UN Human Rights Council.
The actors also profiled 18 members of the European Parliament and journalists and prepared dossiers on UN Special Rapporteurs who had criticized UAE conduct in Sudan.
The significance is not simply that AI can generate propaganda. Political actors have been producing propaganda for centuries. The difference is that AI can make the process much cheaper and more scalable while allowing operators to generate different narratives, personas and documents for different audiences.
The line between genuine grassroots activity and centrally coordinated influence therefore becomes harder to see.
Fraud gets a human face without the human
The report also provides a remarkably concrete example of AI-powered consumer fraud.
A China-based app studio built more than 20 dating applications and used AI personas to communicate with users while advertising the services as fully human. During a two-week period, Anthropic identified more than 4,700 AI personas that interacted with at least 25,000 people.
“A China-based app studio used Claude to both build a network of over 20 dating apps and power the AI personas used to converse with users–despite advertising their service as fully human.” states Anthropic. “Over a two-week window in April 2026, we discovered more than 4,700 distinct AI personas that engaged in conversations with at least 25,000 unique individuals.”
The operation combined AI and human workers. The bots handled large volumes of conversations, while real people performed activities such as video calls and social-media interactions designed to convince victims that they were dealing with genuine users.
The reported ratio was roughly three AI personas for every real person. Claude generated around 2.36 million messages during the period examined.
This is an important preview of how AI could change online fraud. The attacker no longer needs thousands of people to maintain thousands of conversations. A small human operation can supervise a much larger artificial workforce.
The terrorism risk deserves attention
The report does not identify a confirmed terrorist attack conducted with Claude. It does, however, document activity that illustrates why AI-assisted weapons development deserves attention from counterterrorism and national-security agencies.
Anthropic identified six cases involving weapons development, procurement or intelligence gathering in China, Russia and Yemen. The cases include guided rockets, ballistic-missile simulations, anti-torpedo systems, autonomous drone swarms, electronic-warfare targeting and directed-energy weapons.
“We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the “R2000” set) that included a hypersonic glide vehicle variant.” continues the report.
The Yemen case is particularly significant from a terrorism perspective, even though Anthropic does not establish that the actors were a terrorist organization. A weapons-development cell used Claude Code to work on guidance, navigation and control software for a guided rocket. Multiple AI instances were assigned different roles, including coding, research and code review. The group also carried out a real-world test of a guided rocket and returned to the model afterward to analyze the failure.
That distinction matters. AI is not necessarily giving a terrorist group the ability to build an advanced weapons system from nothing. What it can do is reduce the amount of specialized engineering expertise required to modify, integrate and troubleshoot technologies that the group already possesses.
For counterterrorism agencies, this creates a potential new problem: the proliferation of technical capability may no longer depend entirely on recruiting highly specialized engineers.
Weapons development is not limited to missiles
The report provides several other examples.
One China-based actor used Claude to develop documentation and software for an anti-torpedo system, including a technical proposal of more than 200 pages and comparative analysis of US naval systems. The actor repeatedly asked the model to act as a hostile expert and criticize its own work, effectively creating an automated review process.
A Russia-based operation worked on an autonomous FPV drone swarm using Claude Code and simulation infrastructure. Other cases involved electronic warfare, air-defense suppression and intelligence gathering related to directed-energy weapons.
The pattern is consistent: AI can compress research, engineering, documentation and testing cycles.
That does not mean the model independently created these weapons. In several cases, the actors already had expertise, hardware or access to the necessary infrastructure. The AI accelerated the work around them.
Biology is an even harder problem
Biological misuse presents a different challenge because intent is much harder to establish.
Anthropic says today’s models are capable of assisting with increasingly complex scientific research, making it harder to guarantee that they cannot meaningfully support dangerous biological work.
The report describes five cases involving potentially sensitive research. They include gain-of-function work involving chikungunya, planning related to mammalian adaptation of avian influenza, an orthopoxvirus immune-evasion research proposal, optimization of venom peptides and computational redesign of toxins.
Anthropic is careful about what these cases prove. It does not claim that the researchers intended to develop biological weapons, nor that Claude enabled a biological weapon. The cases demonstrate something more subtle: dangerous research can look very similar to legitimate scientific research when viewed one request at a time.
That makes traditional content filtering much harder.
A sophisticated actor does not necessarily have to ask an AI model, “How do I build a biological weapon?” They can divide the work into apparently legitimate scientific tasks and combine the answers elsewhere.
AI is also becoming the target
Perhaps the most strategic part of the report concerns illicit distillation.
Anthropic says several Chinese AI companies attempted to extract capabilities from Claude by creating large numbers of fraudulent accounts, routing enormous numbers of queries through proxy networks and collecting model outputs for training.
Alibaba’s operation reached almost three million exchanges per day from more than 3,500 fraudulent accounts, with more than 151 million exchanges observed between May and July. The activity targeted agentic tasks, software engineering, kernel development and long-horizon reasoning.
Zhipu used hundreds of fraudulent accounts to extract and process reasoning traces. Moonshot, meanwhile, allegedly forwarded customer requests to Claude while presenting Claude’s responses as if they came from its own Kimi models.
The privacy implications are serious as well. Anthropic says some rerouted requests contained sensitive corporate information, live credentials and surveillance data. In one case, DeepSeek allegedly relayed requests containing internal AI-program specifications; another exposed credentials associated with a Russian government database.
This creates a new category of AI supply-chain risk: an organization may think it is using one AI service while its data and workloads are actually being processed by another.
The common thread is scale
The cases in the report look very different, but they point in the same direction.
AI is becoming a force multiplier for cybercriminals, intelligence services, propagandists, fraudsters, surveillance operators and potentially armed groups. It can automate the boring parts of an operation, accelerate the difficult parts and allow a small number of people to coordinate activity at a scale that would previously have required a much larger organization.
This is why the most important finding is not that AI can hack systems or generate malicious code.
The bigger issue is that AI is changing the economics of malicious activity.
A criminal group can process millions of files. A surveillance unit can turn huge volumes of social-media posts into target profiles. A propaganda operation can maintain hundreds of artificial identities. A fraud operation can hold thousands of conversations simultaneously. A weapons program can use AI to accelerate software development and technical analysis.
And in the most advanced cyber cases, AI systems can perform several of these tasks with little human intervention. Anthropic reports that humans still tend to retain the decisions that matter most, such as selecting targets and deciding how to monetize results. But the operational workload between those decisions can increasingly be delegated to machines.
That may be the real security threshold we are crossing.
The question is no longer simply whether AI can be abused. It clearly can.
The more important question is how much of a malicious operation can now be delegated to AI before a human has to step in.
Anthropic’s report suggests that the answer is already: quite a lot.
“Sophisticated and persistent threat actors continuously test our safeguards and try to circumvent the technical measures we use to detect and prevent misuse.” concludes the report. “We’ll continue to evolve our safeguards and coordinate with our partners to improve our ability to detect, disrupt, and prevent future misuse.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini(SecurityAffairs – hacking, Anthropic)